US-CERT Vulnerability Summary for the Week of July 3, 2023
High VulnerabilitiesPrimary Vendor -- ProductDescriptionPublishedCVSS ScoreSource & Patch Infosem-cms -- semcmsFile Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers...
High VulnerabilitiesPrimary Vendor -- ProductDescriptionPublishedCVSS ScoreSource & Patch Infosem-cms -- semcmsFile Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers...
Mozilla has announced that some add-ons may be blocked from running on certain sites as part of a new feature...
Brick-and-mortar retailers and e-commerce sellers may be locked in a fierce battle for market share, but one area both can...
The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius...
Businesses operating in the Latin American (LATAM) region are the target of a new Windows-based banking trojan called TOITOIN since...
Malicious actors exploited an unknown flaw in Revolut's payment systems to steal more than $20 million of the company's funds...
Mastodon, a popular decentralized social network, has released a security update to fix critical vulnerabilities that could expose millions of...
The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius...
CISOs, security leaders, and SOC teams often struggle with limited visibility into all connections made to their company-owned assets and...
Brick-and-mortar retailers and e-commerce sellers may be locked in a fierce battle for market share, but one area both can...
Security researchers observed a new campaign they attribute to the Charming Kitten APT group where hackers used new NokNok malware that...
High VulnerabilitiesPrimary Vendor -- ProductDescriptionPublishedCVSS ScoreSource & Patch Infoapple -- mac_os_xA use after free issue was addressed with improved memory...
Security researchers have dissected a recently emerged ransomware strain named ‘Big Head’ that may be spreading through malvertising that promotes fake Windows...
High VulnerabilitiesPrimary Vendor -- ProductDescriptionPublishedCVSS ScoreSource & Patch Infoapple -- mac_os_xA use after free issue was addressed with improved memory...
Two file management apps on the Google Play Store have been discovered to be spyware, putting the privacy and security...
CISOs, security leaders, and SOC teams often struggle with limited visibility into all connections made to their company-owned assets and...
Progress Software has announced the discovery and patching of a critical SQL injection vulnerability in MOVEit Transfer, popular software used...
Cyber attacks are increasing as the number of vulnerabilities found in software has increased by over 50% in the last...
Mastodon, the free and open-source decentralized social networking platform, has patched four vulnerabilities, one of them critical that allows hackers...
CISA ordered federal agencies today to patch a high-severity Arm Mali GPU kernel driver privilege escalation flaw added to its list of...
MOVEit Transfer, the software at the center of the recent massive spree of Clop ransomware breaches, has received an update...
Image: Bing Image Creator Email and network security firm Barracuda is working to fix an ongoing issue that triggers invalid...
High VulnerabilitiesPrimary Vendor -- ProductDescriptionPublishedCVSS ScoreSource & Patch Infoapple -- mac_os_xA use after free issue was addressed with improved memory...
Google has released its monthly security updates for the Android operating system, addressing 46 new software vulnerabilities. Among these, three...